Safety Sil2 Codesys Safety Sil2

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Codesys Safety Sil2.

By the Year

In 2026 there have been 1 vulnerability in Codesys Safety Sil2 with an average score of 7.2 out of ten. Safety Sil2 did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 1 7.20
2025 0 0.00
2024 0 0.00
2023 16 6.64
2022 0 0.00
2021 0 0.00
2020 1 0.00
2019 3 0.00

It may take a day or so for new Safety Sil2 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Codesys Safety Sil2 Security Vulnerabilities

Monitoring Access Race Condition in Unspecified Product
CVE-2026-79625 7.2 - High - September 30, 2026

Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.

Race Condition

CODESYS Runtime: Unrestricted File Download via CmpApp (CVE-2023-37551)
CVE-2023-37551 6.5 - Medium - August 03, 2023

In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.

Files or Directories Accessible to External Parties

Codesys CmpAppBP Invalid Read DoS
CVE-2023-37552 6.5 - Medium - August 03, 2023

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37553, CVE-2023-37554, CVE-2023-37555 and CVE-2023-37556.

Codesys CmpAppBP Invalid Address Read Enables DoS
CVE-2023-37553 6.5 - Medium - August 03, 2023

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37554, CVE-2023-37555 and CVE-2023-37556.

Codesys CmpApp internal address read CVE-2023-37550
CVE-2023-37550 6.5 - Medium - August 03, 2023

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37547, CVE-2023-37548 and CVE-2023-37549.

Codesys CmpApp DoS via crafted net req causing invalid address read
CVE-2023-37549 6.5 - Medium - August 03, 2023

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37547, CVE-2023-37548 and CVE-2023-37550

Codesys CmpApp Network Request CVE-2023-37548: Denial-of-Service
CVE-2023-37548 6.5 - Medium - August 03, 2023

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37547, CVE-2023-37549 and CVE-2023-37550

Codesys CmpApp DoS via Crafted Network Requests (CVE-2023-37547)
CVE-2023-37547 6.5 - Medium - August 03, 2023

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37548, CVE-2023-37549 and CVE-2023-37550

Codesys CmpApp DoS via Invalid Address Read
CVE-2023-37546 6.5 - Medium - August 03, 2023

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37547, CVE-2023-37548, CVE-2023-37549 and CVE-2023-37550

Codesys CmpAppBP DoS via crafted network request
CVE-2023-37554 6.5 - Medium - August 03, 2023

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37555 and CVE-2023-37556.

Codesys CmpAppForce DoS via Invalid Mem Read (CVE-2023-37559)
CVE-2023-37559 6.5 - Medium - August 03, 2023

After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37558

Codesys CmpAppForce BUG: Authenticated DoS via crafted network requests
CVE-2023-37558 6.5 - Medium - August 03, 2023

After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37559

Codesys CmpAppBP Heap Buffer Overwrite via Authenticated Remote Requests
CVE-2023-37557 6.5 - Medium - August 03, 2023

After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.

Memory Corruption

Codesys CmpAppBP DoS via Crafted Network Requests
CVE-2023-37556 6.5 - Medium - August 03, 2023

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37555.

Codesys CmpAppBP Internal Read Vulnerability Denial of Service
CVE-2023-37555 6.5 - Medium - August 03, 2023

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37556.

Codesys CmpApp invalid read leading to DoS via crafted network requests
CVE-2023-37545 6.5 - Medium - August 03, 2023

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37546, CVE-2023-37547, CVE-2023-37548, CVE-2023-37549, CVE-2023-37550

CODESYS v3 Remote File Access & DoS via Low-Privileged User
CVE-2022-4224 8.8 - High - March 23, 2023

In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.

Insecure Default Initialization of Resource

CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30
CVE-2020-7052 - January 24, 2020

CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.

An issue was discovered in 3S-Smart CODESYS before 3.5.15.0
CVE-2019-9009 - September 17, 2019

An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.

Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.
CVE-2018-20026 - February 19, 2019

Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.

Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
CVE-2018-20025 - February 19, 2019

Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Codesys Safety Sil2 or by Codesys? Click the Watch button to subscribe.

Codesys
Vendor

subscribe